A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring authentication, enabling remote attackers to perform unauthorized model management operations.
Metrics
Affected Vendors & Products
References
History
Thu, 18 Dec 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and including v0.12.3. The platform exposes multiple API endpoints without requiring authentication, enabling remote attackers to perform unauthorized model management operations. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-18T15:13:19.057Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-63389
No data.
Status : Received
Published: 2025-12-18T16:15:54.760
Modified: 2025-12-18T16:15:54.760
Link: CVE-2025-63389
No data.
OpenCVE Enrichment
No data.